ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Over 73k French government workers impacted by instant messaging service breach

The French government’s central digital agency said a data breach impacted over 73,000 government officials who used Tchap, the government’s official encrypted instant messaging service.

 

The Direction interministérielle du numérique, or DINUM, which reports directly to the French prime minister and leads the state’s digital strategy, digital sovereignty, and IT infrastructure transformation, said the data breach occurred after a malicious actor hijacked a government official’s account on Tchap and accessed public conversations.

 

According to DINUM, Tchap hosts both public and private conversations, but the malicious actor could only access public conversations as private conversations between government officials were encrypted. The hacker was still able to access the information of 73,467 officials, representing less than 9% of the registered workforce composed of more than 825,000 people.

 

The agency said that after the breach was identified, it identified the hijacked account and immediately blocked it to remove the attacker’s persistent access and allow for a thorough analysis of the data they were able to access. DINUM was able to verify that the breach compromised users’ full names, email addresses, affiliated entities and avatars.

 

The agency is presently studying event logs from Tchap to "identify the conversations that the attacker was able to access and the nature of the exfiltrated data." DINUM also notified CNIL, the French data protection authority, about the breach incident and the potential compromise of personal data due to the incident.

 

"A message has been sent to all Tchap users reminding them that a public chat room can be found and joined by any user and that its content is not encrypted. In accordance with Tchap’s terms of service, no personal, sensitive, or confidential information should be exchanged in public chats; these exchanges must be reserved for private conversations," DINUM said.

 

"Tchap remains a secure platform for professional exchanges, provided that each user adheres to the terms of service. No personal, sensitive, or confidential information should be exchanged in public chats; these exchanges must be reserved for private conversations," it added.
 
Following DINUM’s announcement, a threat actor using the pseudonym "Misere" announced on a dark web forum that they stole information about more than 70,000 accounts on Tchap, as well as 13.5 gigabytes of data that contained over 643,000 messages.

 

Misere did not state whether they had demanded a ransom from the French government or what they intended to do with the stolen data. The hacker’s account seems to have disappeared since then so their claim could not be independently verified.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543